Cryptocat, Now on iPhone
blog.crypto.cat
blog.crypto.cat
But you are right in that if you don't trust the OS manufacturer not to be snooping on you, you can't trust the app. In addition to logging keystrokes they could be logging the contents of UI text controls as they are set. Even if you implement your own custom keyboard and UI controls and your own encryption prior to sending anything over a socket they could still be snapshotting the phone's framebuffer regularly. There's no way to reliably hide data that you can see visually (or data that has to be unencrypted in memory at some point, even if you don't see it) from the lowest levels of the OS.
Having said all of that, they probably aren't doing any of this, but they could.
> iOS7 provides settings for "background app refresh". Disabling unnecessary app's background refreshing contributes to preventing the potential background monitoring. However, it can be bypassed. For example, an app can play music in the background without turning on its "background app refresh" switch. Thus a malicious app can disguise itself as a music app to conduct background monitoring.
Also, even if you use your own homemade ultra secure OS, you will still be running it on top of the closed source & exploitable broadband chip.
I created a room called: hackernews
Its group fingerprint is: BBD398AA E131E1644 6EF77D4E A2CDC074 F497ED37
I'm not sure the group fingerprint is required. I've noticed if you logout and login with the same room name, it generates a different fingerprint.
It's hard for new users to understand this — the blog post mentions that Cryptocat is trying to make cryptographic authentication less confusing.
I peeked at some of the issues on Github and it looks like they're adding challenge-response for OTP verification so you can have a way to prove identity without an active out of band channel.
> They'll come around to your point of view in time.
The quote from Keynes was merely a slightly whimsical way to make the point that people can hold false beliefs for a very long time, and that it's probably better not to personally invest in the idea that they will come around by themselves in any specific timeframe.
Cryptocat and Telegram seem to be very popular though, proving again that technical superiority isn't really a good indicator of product success. (WhatsApp had terrible security too, at least for a while, but they never went on about how secure they were.)
Making security applications accessible is an important problem to try and solve. Security is difficult and I think they were fairly up front with the potential issues with what they were building.
They've also been doing it for a few years now, the code is open source, they've had professional security audits - what more could they possibly be doing?
IIRC, TextSecure was created by crypto expert[s].